progress
Latest CVEs
The 15 most recently published vulnerabilities affecting progress.
- CVE-2026-16137Path traversal via unsanitized upload filename leads to arbitrary file write in Progress ShareFile Storage Zones Controller7.2
- CVE-2026-16138Remote code execution via unsafe deserialization in Progress ShareFile Storage Zones Controller's CICO service8.0
- CVE-2026-16139Arbitrary file write via path traversal in Progress ShareFile Storage Zones Controller potentially leading to remote code execution7.2
- CVE-2026-65941WhatsUp Gold versions prior to 26.0.2 contain an unauthenticated remote code execution vulnerability in an internal report scheduling service.8.8
- CVE-2026-65940WhatsUp Gold versions prior to 26.0.2 excessive file system permissions allows a privileged attacker to write arbitrary files to a web-accessible location on the host server.6.8
- CVE-2026-65939WhatsUp Gold versions prior to 26.0.2 contain an arbitrary file write vulnerability in the LogToFile action handler.6.8
- CVE-2026-65938WhatsUp Gold versions prior to 26.0.2 contain an improper authorization vulnerability in the Scheduled Reports API.4.3
- CVE-2026-65937WhatsUp Gold versions prior to 26.0.2 contain multiple stored cross-site scripting (XSS) vulnerabilities across the web UI8.0
- CVE-2026-9203Server-side request forgery in Progress MarkLogic Server8.5
- CVE-2026-9195Cross-site scripting in Progress MarkLogic Server Query Console9.3
- CVE-2026-9193Privilege escalation in Progress MarkLogic Server Hadoop integration9.9
- CVE-2026-9192Authentication bypass in Progress MarkLogic Server ODBC App Server9.8
- CVE-2026-9190HTTP request smuggling in Progress MarkLogic Server9.1
- CVE-2026-8709Privilege escalation in Progress MarkLogic Server REST document patch operation9.9
- CVE-2026-7557SAML authentication bypass in Progress MarkLogic Server9.1